OpenPGP encryption
Looking to store secrets with your Ledger? Start with the Ledger Key Ring. It encrypts any file or text, needs the device only once at setup, and is recoverable from your seed. Use OpenPGP if you already work with GnuPG or need every decryption to require the device.
For advanced users. This app is intended for developers already proficient with OpenPGP and GnuPG.
Back up your keys. Keys are wiped by app updates, OS updates, and app reinstalls unless you back them up. Follow the backup and restore instructions in the app-openpgp repository — losing your keys means losing access to anything encrypted against them.
Your Ledger can hold an OpenPGP private key that controls access to encrypted secrets—files, environment variables, API tokens, and other sensitive material your agents or tools consume. Because the private key never leaves the device, anything encrypted against your Ledger is unreadable without it physically present.
How it works
When you set up OpenPGP on your Ledger, a key pair is generated and stored on the device. You encrypt sensitive material against that public key. From that point, decryption requires the Ledger to be connected. Unplug the device and the secrets are opaque ciphertext to any process on the machine—including agents.
A stricter mode requires a manual tap on the device for each decryption event. In that mode, your Ledger becomes an active approval gate: even a process already running on your machine cannot read a secret without your explicit, on-device confirmation.
Which one should I use?
| Point | Ledger Key Ring | OpenPGP |
|---|---|---|
| Device needed | Once for ring init; not for encrypt or decrypt. | For every decryption. |
| Network needed | Yes, for encrypt and decrypt to restore the Ledger Sync trustchain. | No network requirement for encryption or decryption. |
| Behavior after OS update | No OS-update-specific behavior is documented. If setup must be restored, set up a new machine from the same Ledger seed; see Recovery. | Keys are wiped by OS updates and must be restored from a backup. |
| Recovery | If you lose the local password or replace the device, use a new machine with the same Ledger seed and run wallet-cli ring init; choose a new local password. | Restore the OpenPGP key backup following the app-openpgp repository . |
| Known limits | Removing a Ledger Sync member rotates the key, so existing ciphertext must be re-encrypted before removal. | Intended for advanced OpenPGP/GnuPG users; private keys do not persist through app updates, OS updates, app reinstalls, or device replacement without a backup. |
| Best use | personal secrets, tokens, env files, backups, from a terminal or an agent. | Existing GnuPG workflows that need every decryption to require the device. |
In the context of AI tools
This matters most in agent workflows where automation handles sensitive material. An agent that needs API keys or credentials to do its work can only access those secrets when your signer is present. In tap-required mode, it needs your confirmation for every individual access. For general-purpose agent secrets, files, tokens, and backups, use the Ledger Key Ring instead.
Further reading
- OpenPGP on Ledger : setup and usage in the Ledger Help Center
- Ledger Key Ring: encrypt secrets from a terminal or an agent